验证
L2 · 结构化
安全
中风险
健康
活跃
信任
银
功能介绍AI
Integrates WPS/KDocs cloud documents into DeepSeek Harness, enabling natural language file operations like listing, reading, creating, uploading, and searching.
- One-click browser authorization
- List, read, create, upload, and search docs
- Works via chat or API calls
由 AI 基于 README 自动生成,仅供参考。
安装
dsh plugin --profile web add github:handsomeboyck/dsh-wps-plugingsInstall method: GitHub · 尚未在容器中测试 (L3+)
兼容性
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
要求
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
安全报告
自动静态扫描,非人工审核。
DSH.SO AUDIT需注意1ba184
安全审查自动审查 · 每日更新
需注意
非阻断类别中的严重发现(动态执行、shell 执行、安装脚本、混淆)。在 CLI/终端插件中常见,但值得审查。
2 严重·2 警告·5 提示·14 扫描文件数
code-exec ×1shell ×1插件版本
0.2.1dsh 清单扫描版本
1ba184342ba42026-08-20当前版本
1ba184342ba4扫描结果仅对「扫描版本」有效。扫描后 7 天内的新提交不会触发 outdated,评级仍然有效;超过 7 天未重新扫描才显示 outdated。
免责声明:这是自动化静态分析,不构成安全保证。安装前请自行审查。
第二意见扫描(vet · 并行评估期)
vet:干净vet 判定:vet:干净 · score 87
- R3 · info [certain] — 裸 process 引用(可能为 typeof 探测)
- R6 · info [heuristic] — 字符串特征:child_process 引用
- R2 · medium [likely] — require() 动态模块加载(npm 包内能力触达)
- R3 · info [certain] — 只读 process 成员(能力触达面):process.cwd
- R11 · medium [likely] — 删除文件操作:fs.unlink(清理操作常见,交由 LLM 审计复核上下文)
vet 仅作参考,不改变 dsh 的四档等级。
风险:中风险2 critical · 2 warning · 5 info
• 静态启发式扫描:已完成(14 个文件)
• 依赖漏洞:需深度审计(L3+)
• 权限沙箱:需运行时测试(L4+)
高危发现 · 4 / 4
- critical使用 child_process 子进程模块(Node.js)src/auth/browser-auth.ts:203const { execSync } = await import('child_process');
- critical执行 shell 命令(exec / execSync)src/auth/browser-auth.ts:204execSync(`${command} ${args.join(' ')}`, { stdio: 'ignore' });
- warning向裸 IP 地址发起 HTTP 请求src/auth/browser-auth.ts:152console.log(`[WPS Auth] 本地服务器已启动: http://127.0.0.1:${addr.port}`);
- warning文件系统写入操作src/auth/token-store.ts:66await fs.writeFile(TOKEN_FILE, JSON.stringify(tokenInfo, null, 2), 'utf-8');
静态启发式扫描,可能误报——使用前请自行审查源码。
活跃度
最近提交 2026-08-20 · 活跃度:活跃
• 仓库创建: 2026-08-20
• 星标: ★ 3 · 复刻: 0
• 健康度: 活跃 — 近 30 天有提交
